Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80986

net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages
Back to all
CVE

CVE-2026-80986

net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages

In the Linux kernel, the following vulnerability has been resolved:

net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages

On a link whose device has maxrecvsge == 1 there is no shared v2 receive

buffer, and smcllcsaveaddlink_rkeys() takes the v2 extension from 44

bytes past the start of the queue entry's inline message:

  ext = (struct smcllcmsgaddlinkv2ext *)(llcmsg + SMCWRTXSIZE);

The entry is a 72-byte allocation and the extension starts at offset 68, so

ext->num_rkeys at offset 94 is already past it. This happens on every

SMC-Rv2 link addition, whatever the peer sends:

  [    2.490065] BUG: KASAN: slab-out-of-bounds in smcllcsaveaddlink_rkeys+0x333/0x350

  [    2.490431] Read of size 2 at addr ffff8880056406de by task smctest/106

  [    2.490709]

  [    2.490792] CPU: 0 UID: 0 PID: 106 Comm: smctest Not tainted 7.2.0-rc5-p1-g77a5d9d9c99f #32 PREEMPT(lazy)

  [    2.490795] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014

  [    2.490798] Call Trace:

  [    2.490803]  <TASK>

  [    2.490805]  dumpstacklvl+0x53/0x70

  [    2.490810]  print_report+0xd0/0x630

  [    2.490828]  ? pfxrawspinlock_irqsave+0x10/0x10

  [    2.490832]  ? smcllcsaveaddlink_rkeys+0x333/0x350

  [    2.490834]  kasan_report+0xce/0x100

  [    2.490836]  ? smcllcsaveaddlink_rkeys+0x333/0x350

  [    2.490837]  smcllcsaveaddlink_rkeys+0x333/0x350

  [    2.490839]  ? smcrbufmap_lgr+0x1bf/0x2b0

  [    2.490844]  smcllccliaddlink+0xca7/0x1e80

  [    2.490848]  ? smcllcwait+0x355/0x810

  [    2.490850]  ? _pfxsmcllcwait+0x10/0x10

  [    2.490851]  ? _pfxsmcllccliaddlink+0x10/0x10

  [    2.490853]  ? _pfxautoremovewakefunction+0x10/0x10

  [    2.490863]  _smcconnect+0x3f5c/0x4980

  [    2.490873]  ? _pfxkernel_connect+0x10/0x10

  [    2.490888]  ? pfxsmcconnect+0x10/0x10

  [    2.490891]  ? release_sock+0x148/0x1d0

  [    2.490894]  smc_connect+0x42c/0x580

  [    2.490896]  _sysconnect+0xfc/0x130

  [    2.490898]  ? pfxsysconnect+0x10/0x10

  [    2.490900]  ? handlemmfault+0x1a1/0x430

  [    2.490908]  _x64sys_connect+0x6d/0xb0

  [    2.490909]  ? fpregsassertstate_consistent+0x56/0xe0

  [    2.490917]  dosyscall64+0xf9/0x540

  [    2.490921]  entrySYSCALL64afterhwframe+0x77/0x7f

  [    2.490924] RIP: 0033:0x421bb4

  [    2.490927] Code: ff f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 80 3d ad 34 09 00 00 74 13 b8 2a 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 4c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 55

  [    2.490929] RSP: 002b:00007ffd473b01a8 EFLAGS: 00000202 ORIG_RAX: 000000000000002a

  [    2.490935] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000421bb4

  [    2.490936] RDX: 0000000000000010 RSI: 00007ffd473b01d0 RDI: 0000000000000003

  [    2.490937] RBP: 0000000000003930 R08: 0000000000000004 R09: 0000000000000000

  [    2.490938] R10: 00007ffd473b0f98 R11: 0000000000000202 R12: 0000000000000006

  [    2.490939] R13: 00007ffd473b0f87 R14: 0000000000000003 R15: 00007ffd473b0f90

  [    2.490940]  </TASK>

  [    2.490941]

  [    2.499545] Allocated by task 44:

  [    2.499693]  kasansavestack+0x33/0x60

  [    2.499860]  kasansavetrack+0x14/0x30

  [    2.500026]  _kasankmalloc+0x8f/0xa0

  [    2.500190]  _kmalloccache_noprof+0x158/0x370

  [    2.500393]  smcllcenqueue+0x72/0x560

  [    2.500559]  smcwrrxtaskletfn+0x474/0xa80

  [    2.500747]  taskletactioncommon+0x20f/0x8a0

  [    2.500945]  handle_softirqs+0x18e/0x590

  [    2.501115]  do_softirq+0x3b/0x60

  [    2.501266]  _localbhenableip+0x61/0x70

  [    2.501446]  _allocskb+0x732/0x890

  [    2.501604]  rxeinitpacket+0x16b/0x4f0

  [    2.501783]  prepareackpacket+0xb8/0x830

  [    2.501962]  rxe_receiver+0x495/0x96e0

  [    2.502125]  do_work+0x144/0x470

  [    2.502269]  processonework+0x633/0x1030

  [    2.502450]  worker_thread+0x45b/0xd10

  [    2.50261

---truncated---

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/2d1e7c5aaa3326e95e2058457f172ca99a9a4577, https://git.kernel.org/stable/c/486c699a8cde82c1d9b4f443eeab4ddf86358cb0, https://git.kernel.org/stable/c/5e5d9e6df677d30a2203d257b5fd8b99814fa607, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80986.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80986, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00649%
EPSS Percentile
0.49537%
Introduced Version
27ef6a9981fe74191849966a6d5e0400a4008ab8,6.14.0,6.19.0,0
Fix Available
2d1e7c5aaa3326e95e2058457f172ca99a9a4577,6.18.50,7.2.4

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading